
Terraform Security & IaC Scanning
Practice Terraform Security & IaC Scanning by producing and reviewing portable evidence without requiring unavailable host, cloud, hardware, or multi-node access.
Briefing
Objectives
- 1Prepare workspace and verify tooling
- 2Prepare local target for Terraform Security & IaC Scanning
- 3Execute Terraform Security & IaC Scanning technique
- 4Capture evidence
- 5Complete TFSec Scanner
- 6Complete Checkov Runner
- 7Tune and interpret
- 8Compile and verify submission
Flags
Submit the verifiable output value for Checkov Runner as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the verifiable output value for S3 Fixer as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the verifiable output value for Sentinel Enforcer as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the verifiable output value for Drift Detector as produced by the local tool on 127.0.0.1 (e.g., version, status, IP, or header).
Submit the key finding or status reported by the scan for TFSec Scanner (e.g., open, 200, or version string from local output).